Tony (@tonyysec) 's Twitter Profile
Tony

@tonyysec

Bug bounty hunter

ID: 1470315408276131840

calendar_today13-12-2021 08:51:34

13 Tweet

2 Followers

51 Following

Kathan Patel (@kathanp19) 's Twitter Profile Photo

Here are my SAML Notes; I will be gradually updating HowToHunt; please enjoy. 😊 github.com/KathanP19/HowT… #bugbounty #bugbountytips #cybersecurity

TheMayor - Joe Helle (@joehelle) 's Twitter Profile Photo

It's time to look beyond Offensive Security in this industry. Training diversity matters when building diverse teams, and that applies to any field. If you're a hiring manager, take note of some of these alternatives you may see on resumes and accept them. A thread 🧵

Ben Sadeghipour (@nahamsec) 's Twitter Profile Photo

Alright - Lots of you really wanted Shodan Subscriptions. Reply with your favorite shodan search query and I'll pick 5 winners to get a free Shodan voucher :).

Benchmarkkk (@heybenchmarkkk) 's Twitter Profile Photo

Spent some time to hunt XSS but the application gave an error stating "The requested URL was rejected. Please contact with your administrator". Almost gave up and then tried this payload and boom 💥, XSS popped up. #bugbounty #bugbountytip #XSS #wafbypass #Cloudflare

Spent some time to hunt XSS but the application gave an error stating "The requested URL was rejected. Please contact with your administrator".
Almost gave up and then tried this payload and boom 💥, XSS popped up.
#bugbounty #bugbountytip #XSS #wafbypass #Cloudflare
Omar Ωr Santos (@santosomar) 's Twitter Profile Photo

Geowifi - Search WiFi Geolocation Data By BSSID And SSID On Different Public Databases ift.tt/AtLa7fX #cybersecurity #bugbountytips #hacking #tools

Geowifi - Search WiFi Geolocation Data By BSSID And SSID On Different Public Databases ift.tt/AtLa7fX #cybersecurity #bugbountytips #hacking #tools
Ynoof (@ynoofassiri) 's Twitter Profile Photo

Account takeover due to unicode normalization issue. - Victim account: [email protected] - Attacker account: ynoⓞ[email protected] Due to no validation send to the email and some unicode issues , this leads to account takeover. Thanks Hussein Daher for the idea. #bugbountytips

Account takeover due to unicode normalization issue.

- Victim account: ynoof@hotmail.com
- Attacker account: ynoⓞf@hotmail.com

Due to no validation send to the email and some unicode issues , this leads to account takeover.
Thanks <a href="/HusseiN98D/">Hussein Daher</a> for the idea.
#bugbountytips